cancel
Showing results for 
Search instead for 
Did you mean: 

GRC AC 10.1 - Re-Assign Business Process for Access Risk ID

Former Member
0 Kudos

Hello

We are thinking of updating the business processes assigned to standard access risks that are segregation of duties type. Before making any changes we wanted to understand if there would be any adverse impacts to changing it? For example, we know that the first letter of the access risk ID is related to the business process (e.g. F = Finance). Changing the assigned business process would disconnect that relationship but does that matter? Or do we need to create a custom access risk ID using the naming convention of the new business process? For example, if you changed F002 from finance to Order to Cash should we create a new access risk called ZS002 and make the old risk inactive?

Any help is appreciated. I wasn't able to find much information about the link between business process and access risk ID.

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Hi Stacey,

Risks are made up of functions, and technically will have no impact on calculation of risk.

The 'access rule summary', in Report and Analytics' tab has Risk against Business process. So, this report will be impacted.This report will show risks, but the Business process will have a changed naming convention, in comparison to previous month.



Regards

Plaban

Answers (1)

Answers (1)

madhusap
Active Contributor
0 Kudos

Hi Stacey,

Business process is more to link your risks to different business processed like MM,FI,SD,TRM etc.

You can create your own business process and can link it your risk ID. Unless you have any BRF+ rules which are used to determine approvers for your Risks based on business process, I dont think there will be any impact.

Regards,

Madhu.